News

Vulnerability-Lookup 6.2.0 released

We are pleased to announce the release of Vulnerability-Lookup 6.2.0! This release is centred on the KEV catalogs. A producer can now withdraw one of its own assertions, as GCVE BCP-07 2.3 specifies, and the withdrawal propagates to the mirrors instead of vanishing. The KEV catalogs page gains three cards that read what the listings rest on: the evidence behind them, the profile of the vulnerabilities they list, and their weekly trends. An organization page now tells what an organization is affected by, published as a GNA and assigned as a CNA, and the dashboard gets an Other sources tab covering every feed outside the CVE and GCVE programs. Also in this release: similarity searches over the ATT&CK bi-encoder, a Prometheus endpoint, the amended GCVE-BCP-05 identifier placement, BCP-03 static feeds, a site notice, three new OSV sources and a generated OpenAPI snapshot.

Read more →

September 18, 2026

What Do KEV Catalogs Actually Know? Evidence, Lead Time and Zero-Days Across Five Catalogs

A Known Exploited Vulnerabilities (KEV) catalog is a list of vulnerabilities somebody asserts are being exploited in the wild. CISA publishes the best-known one. Vulnerability-Lookup aggregates five of them on its public instance — CISA KEV, the ENISA catalog, The Shadowserver Foundation’s honeypot observations, Previdian’s aggregation, and CIRCL’s own catalog — all expressed in the same GCVE BCP-07 format, so that they can be compared rather than merely browsed. Since June, the KEV catalogs page has shown which catalog lists which vulnerability. This post is about two new sections that answer the next two questions: why does a catalog say a vulnerability is exploited, and when does it say so relative to everything else we know about the vulnerability? Along the way they surface a population that is easy to overlook: vulnerabilities listed as exploited before their CVE was even published.

Read more →

September 13, 2026

Vulnerability Report - August 2026

All vulnerability reports Introduction This vulnerability report has been generated with the help of AI, using the VulnMCP tooling on top of Vulnerability-Lookup, with contributions from the platform’s community.

Read more →

September 6, 2026

Vulnerability-Lookup 6.1.0 released

We are pleased to announce the release of Vulnerability-Lookup 6.1.0! This release brings a native EUVD API: an instance now exposes the EUVD identifiers it allocates through its own /api/euvd namespace, with listing, lookup by any correlated alias, advisory mapping, and a search endpoint that pages over the whole corpus. The CVE Program hierarchy arrives on the website as CNA roots — a root: search operator, a new dashboard tab and per-root feeds. A CPE-Editor instance can be plugged into the vulnerability page, the frontend libraries are now managed with npm, and administrators get an activity report of their local CNA/GNA over any date range. On top of that: sighting summaries on bundles, a Markdown export of the recent vulnerabilities, the CVE Program’s bundle warning, a storage fix that matters to every instance running on a modest host, and a batch of security fixes.

Read more →

September 2, 2026

From Gold Datasets to AI Agents: VulnMCP 2.0.0, ML-Gateway 1.4.0, and VulnTrain 3.2.0

Today we are releasing an entire chain at once. VulnTrain 3.2.0 turns a hand-curated gold dataset of CVE-to-ATT&CK mappings into a published multi-label classifier — with the methodology now on arXiv. ML-Gateway 1.4.0 serves that model (and its siblings) over a local REST API, hardened against real-world inputs. And VulnMCP 2.0.0 puts the whole thing — plus the Vulnerability-Lookup API, KEV catalogs, sightings, the GCVE registry, and now the CNA partners of the CVE Program — one tool call away from any MCP-capable AI agent.

Read more →

August 30, 2026

Vulnerability Report - July 2026

All vulnerability reports Introduction This vulnerability report has been generated with the help of AI, using the VulnMCP tooling on top of Vulnerability-Lookup, with contributions from the platform’s community.

Read more →

August 14, 2026

Vulnerability-Lookup 6.0.0 released

We are pleased to announce the release of Vulnerability-Lookup 6.0.0! This release is centred on two themes. Notifications leave the e-mail-only world: a subscription can now push its reports to any HTTPS endpoint — a chat channel, a SIEM, a ticketing system — with a configurable payload, under a strict outbound policy. And the local exploit hazard model moves from an experiment to a first-class citizen of the platform: two new API endpoints, hazard-ordered reports, per-subscription parameters and daily standing exposure alerts. On top of that: a vulnerability credits index with rankings and search, SSVC v2.0 decisions on the CVE page, an import_dump command to bootstrap an instance from the public dumps, and a batch of security fixes.

Read more →

August 13, 2026

From a Research Paper to Running Code: Experimenting with Local Exploit Hazard in Vulnerability-Lookup

One of the interesting characteristics of open-source security tooling is that it gives us a relatively direct path from research to experimentation. On 27 July 2026, Stephen Shaffer and Laura Voicu published the first version of Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency on arXiv. The paper proposes turning global exploit-likelihood estimates such as EPSS into a local exploit hazard that can account for an organization’s controls, vulnerability age and exposure context.

Read more →

August 11, 2026

Vulnerability-Lookup 5.5.0 released

We are pleased to announce the release of Vulnerability-Lookup 5.5.0! This is a big one. The legacy admin flags give way to full Role-Based Access Control: roles, permissions, global and per-resource assignments, creation policies and dedicated management UIs, enforced across the views and the APIs. The vulnerability page gains AI-suggested MITRE ATT&CK techniques, inferred from the vulnerability description by a model trained with VulnTrain. On top of that: an EUVD ID allocation and creation pipeline, feeder supervision with automatic respawning and CSAF backoff, new VEX enrichment sources (SUSE and Microsoft MSRC) with a VEX records browse view, new feeders for Rocky Linux, Ubuntu and TuxCare, and a redesigned admin interface.

Read more →

July 24, 2026

Vulnerability-Lookup 5.4.0 released

We are pleased to announce the release of Vulnerability-Lookup 5.4.0! The highlight of this release is VEX enrichment: a new feeder ingests Red Hat’s per-CVE CSAF VEX documents and attaches them to the corresponding vulnerabilities, surfaced through new /api/vex endpoints, a VEX tab on the vulnerability page and a VEX badge in the vulnerability header. Administrators gain per-user control over CNA publication with a dedicated credentials overview, the admin dashboard was modernized, and a batch of feeder robustness fixes makes the CSAF and VARIoT feeders much better behaved on partial failures.

Read more →

July 10, 2026